Git Product home page Git Product logo

enscript's Introduction

EnScript utilities for speeding up investigations

AddImages.EnScript

This script allows several disk images to be imported at the same time. To use, first open a case and run the AddImages.EnScript script. Select a directory with images to process, then select the checkboxes next to the images you wish to import. Click OK. The images will be added to the case.

The tool accepts two file extensions:

  • .img: Imported as a raw, full-disk image
  • .E01: Imported as an EnCase evidence file

CreateHashSet.EnScript

This script will create a list of hashes from the selected files and then extract them so we can compare them with the list of whitelist or blacklist hashes. This script will calculate md5 and sha1 hashes.

FindPrintJobs.EnScript

This script will iterate all the files inside the evidence and look for the printed job, cached inside the image. Because a user can change the location of spool location we did not limited our search only to that folder but we looked for every file with the spool print extension (SPL).

MismatchedExtensions.EnScript

This tool iterates through the files in all evidence in the current case, and identifies files which have a file extension that doesn't match the file signature. This can be used to find files that have been renamed with a different extension to hide their contents. To use the tool, simply open a case and run the MismatchedExtensions.EnScript script. The script will display a window presenting the found files, and also add them to bookmarks within the case.

ScanRegistry.EnScript

This script will parse the set registry key and look for a value. The ideal use of this script is to have a list of blacklisted softwares to see if those software are installed on the end point or we can have a list of default setting for the endpoint registry to make sure that the used has not change them.

enscript's People

Contributors

liptonb avatar aidinski avatar

Watchers

 avatar James Cloos avatar  avatar  avatar  avatar

Forkers

slad99

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    ๐Ÿ–– Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. ๐Ÿ“Š๐Ÿ“ˆ๐ŸŽ‰

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google โค๏ธ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.